Google Cloud / Mandiant (GTIG)
mandiant-gtig · B · active
https://cloud.google.com/blog/topics/threat-intelligence
Google Threat Intelligence Group; absorbed Mandiant CTI. The /topics/threat-intelligence landing lists titles but NO publication dates (only relative read times). Drill rule: open the top 3-5 posts on the listing and read their date inline rather than treating the dateless landing as empty. RSS at https://cloud.google.com/blog/topics/threat-intelligence/rss is a partial mirror (truncated). (v2.55: rss_url verified — use `python3 tools/fetch_source.py feed https://feeds.feedburner.com/threatintelligence/pvexyqv7v0v [N]`) | 2026-06-20 full audit (v2.62): live=Y, drill=Y. FETCH → feed https://feeds.feedburner.com/threatintelligence/pvexyqv7v0v 5 (dated listing) then webfetch the per-article cloud.google.com URL for the body; the HTML landing also works for titles but carries no dates. AVOID: The /topics/threat-intelligence HTML landing has titles but NO publication dates (only relative read-times) — use the feedburner RSS for dates rather than treating the dateless landing as the index. The cloud.google.com/.../rss mirror is truncated.. | 2026-07-05 admiralty audit: B — GTIG/Mandiant original first-hand threat research. Reliability HIGH->B, status stays active. Use feedburner RSS for dates (HTML landing is dateless).
Cited in 34 entries
Citation cadence
Citation days per ISO week (10 weeks of coverage span, total 21).
- Trust-primitive forgery was a research theme this week: recovering live ADFS signing keys, and minting a second 'Verified' GitHub commit2026-07-12
- Mandiant "Ghost in the Database": recovering an active ADFS token-signing key from Machine DPAPI when the WID/DKM Golden SAML path fails2026-07-09
- ShinyHunters / UNC6240 Oracle campaign — status update: Nissan is the largest named victim, notifications keep landing, and a separate Medtronic claim surfaces2026-07-05
- Two internet-facing Oracle enterprise product lines were under active exploitation this week — E-Business Suite RCE joins the PeopleSoft campaign2026-07-05
- Law-enforcement and platform-disruption momentum this week — NetNut/Popa proxy botnet dismantled, StegoAd extension cluster killed, $10M bounty on Russia-nexus crews2026-07-05
- Google, FBI, Lumen and Shadowserver disrupt the NetNut (Popa) residential-proxy botnet2026-07-04
- Threat-actor developments: Russia-nexus espionage broadens; new China-nexus and DPRK clusters2026-06-29
- ShinyHunters / UNC6240 Oracle PeopleSoft campaign2026-06-29
- Looking ahead — 2026-W262026-06-29
- CVE-2026-20245 — Cisco Catalyst SD-WAN Manager: Mandiant reconstructs the full zero-day chain2026-06-29
- Turla's STOCKSTAY: a four-component .NET backdoor for diplomatic intelligence collection2026-06-27
- Mandiant documents the full Cisco Catalyst SD-WAN exploitation chain — CSV-injection to a root backdoor2026-06-27
- Mandiant publishes the forensic reconstruction behind Cisco SD-WAN Manager CVE-2026-202452026-06-26
- Cisco Catalyst SD-WAN Manager CVE-2026-202452026-06-26
- ShinyHunters extortion brand — Council of Europe named, Kodak and One Medical added to the leak-site pressure2026-06-22
- PRC UNC6508 ran year-plus espionage through internet-facing REDCap servers and a Google Workspace BCC rule2026-06-16
- Education — ShinyHunters' PeopleSoft campaign lands disproportionately on universities2026-06-14
- CVE-2026-35273 — Oracle PeopleSoft: confirmed zero-day exploited by ShinyHunters (UNC6240), education sector hit hardest2026-06-14
- Oracle PeopleSoft CVE-2026-35273 attributed to ShinyHunters; confirmed zero-day, 100+ victims, education sector hit hardest2026-06-13
- CVE-2026-48558 — SimpleHelp RMM: unauthenticated OIDC authentication bypass yields a full technician session2026-06-13
- ShinyHunters PeopleSoft campaign — Oracle confirms CVE-2026-35273 and ships an out-of-band patch; Nottingham quantifies 455,000 records2026-06-12
- Unit 42: Microsoft Teams external-chat now a primary phishing surface for APT29 and UNC66922026-06-09
- Luna Moth / Silent Ransom Group (UNC3753): vishing-to-physical-access data-theft extortion against legal and professional services2026-06-06
- Luna Moth / UNC3753: vishing-to-physical-USB data-theft extortion reaches ~$20 M suppression payment and DNS fast-flux C22026-06-01
- Google's threat-intel group maps a Chinese-language PhaaS ecosystem doing real-time OTP relay over RCS/iMessage2026-05-26
- CVE-2026-5426 — Digital Knowledge KnowledgeDeliver LMS: pre-shared ASP.NET machineKey enables ViewState deserialization RCE, exploited as a zero-day2026-05-26
- UNC6671 / BlackFile — GTIG publishes the full profile; group announced shutdown "under this name", rebrand probable2026-05-25
- CVE-2026-5426 — Digital Knowledge KnowledgeDeliver LMS: ViewState deserialization RCE exploited as a zero-day2026-05-25
- GTIG: UNC6671 "BlackFile" vishing → AiTM → rogue-MFA → programmatic SharePoint exfiltration of 1M+ files per victim; DLS shutdown signals probable rebrand2026-05-16
- GTIG AI Threat Tracker (May 2026): First Confirmed AI-Generated Zero-Day Exploit ITW and the Behavioural Class of AI-Augmented Malware2026-05-12
- GTIG AI Threat Tracker (May 2026) — first AI-generated zero-day exploit ITW2026-05-11
- Qilin / Agenda RaaS — Die Linke confirms Q2 2026 German activity continuity2026-05-04
- Mandiant M-Trends 20262026-05-04
- Google Threat Intelligence Group — Europe data-leak landscape 20252026-05-04